CERT-In Advisory
CIAD-2021-0012
Multiple Vulnerabilities in Microsoft Exchange Server
Original Issue Date: March 03, 2021
Severity Rating: High
Software Affected
- Microsoft Exchange Server 2019 Cumulative Update 7
- Microsoft Exchange Server 2019 Cumulative Update 8
- Microsoft Exchange Server 2016 Cumulative Update 18
- Microsoft Exchange Server 2016 Cumulative Update 19
- Microsoft Exchange Server 2013 Cumulative Update 23
Overview
Multiple vulnerabilities have been reported in Microsoft Exchange Server which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
Multiple vulnerabilities exist in Microsoft Exchange Server due to untrusted connection with Exchange Server on port 443. A remote attacker could exploit these vulnerabilities by enticing the target user to open a specially crafted file.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Solution
Apply appropriate patches as mentioned in:
https://msrc.microsoft.com/update-guide/en-us/
Organizations are strongly recommended to run the Test-ProxyLogon.ps1 script that scans Exchange log files for indicators of compromise (IOCs) associated with the vulnerabilities
https://github.com/microsoft/CSS-Exchange/tree/main/Security
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065
References
Microsoft
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2021-exchange-server-security-updates/ba-p/2175901
https://github.com/microsoft/CSS-Exchange/tree/main/Security
US-CERT
https://us-cert.cisa.gov/ncas/alerts/aa21-062a
CVE Name
CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
CVE-2021-26412
CVE-2021-26854
CVE-2021-27078
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|